Skip to main content

SecurityOutput

Struct SecurityOutput 

Source
pub struct SecurityOutput<Config, Gate> {
Show 14 fields pub schema_version: SecuritySchemaVersion, pub version: ToolVersion, pub elapsed_ms: ElapsedMs, pub config: Config, pub gate_outcomes: Option<GateOutcomes>, pub request_outcomes: Option<RequestOutcomes>, pub meta: Option<Meta>, pub gate: Option<Gate>, pub workspace_diagnostics: Vec<WorkspaceDiagnostic>, pub security_findings: Vec<SecurityFinding>, pub attack_surface: Option<Vec<SecurityAttackSurfaceEntry>>, pub unresolved_edge_files: usize, pub unresolved_callee_sites: usize, pub unresolved_callee_diagnostics: Option<SecurityUnresolvedCalleeDiagnostics>,
}
Expand description

The fallow security --format json envelope. FallowOutput discriminates it by the kind: "security" tag; the optional gate block is additive and is not part of that discrimination.

Fields§

§schema_version: SecuritySchemaVersion

Schema version of this envelope.

§version: ToolVersion

Fallow CLI version that produced this output.

§elapsed_ms: ElapsedMs

Wall-clock milliseconds spent producing the report.

§config: Config

Privacy-safe config context relevant to security candidate generation.

§gate_outcomes: Option<GateOutcomes>

The verdict of every gate this run evaluated, keyed by name. The CLI always emits it, with the command’s default exit rule in it also when no flag armed a gate, so a CI integration reads the verdict instead of guessing from a process status it usually cannot see. A gate fails the build when status is fail AND enforced is true. The typed programmatic API runs no CLI gate and leaves it absent. See crate::GateOutcomes.

§request_outcomes: Option<RequestOutcomes>

Every narrowing or shaping request this run RECEIVED, keyed by name, absent when it was asked for nothing. An entry whose status is not applied means the run could not do what it was asked and reported something WIDER instead, so what follows is a valid report of a scope nobody requested. Honoured requests are published too, with status: "applied", so an absent object means “nothing was asked for”, never “nothing failed”. See crate::RequestOutcomes.

§meta: Option<Meta>

Security-specific rule and field metadata, emitted with --explain.

§gate: Option<Gate>

Gate verdict, present only when --gate <mode> was set (issue #886). Emitted on pass too (verdict: "pass", new_count: 0) so consumers distinguish “gate ran and passed” from “gate did not run” (absent).

§workspace_diagnostics: Vec<WorkspaceDiagnostic>

Diagnostics owned by this security analysis run.

§security_findings: Vec<SecurityFinding>

Security candidates. Paths are project-root-relative, forward-slash.

§attack_surface: Option<Vec<SecurityAttackSurfaceEntry>>

Opt-in attack-surface inventory from untrusted entry points to reachable sinks. Present only when --surface was requested.

§unresolved_edge_files: usize

In-band blind spot: number of "use client" files whose transitive import cone contains a dynamic import() the reachability BFS could not follow. A leak hidden behind such an edge would not be reported, so a zero finding count with a non-zero value here is NOT a clean bill.

§unresolved_callee_sites: usize

In-band blind spot: number of sink-shaped nodes the catalogue detector could not flatten to a static callee path (dynamic dispatch, computed members, aliased bindings). A zero finding count with a non-zero value here is NOT a clean bill.

§unresolved_callee_diagnostics: Option<SecurityUnresolvedCalleeDiagnostics>

Bounded diagnostics for unresolved callee blind spots.

Trait Implementations§

Source§

impl<Config: Clone, Gate: Clone> Clone for SecurityOutput<Config, Gate>

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<Config: Debug, Gate: Debug> Debug for SecurityOutput<Config, Gate>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<Config, Gate> Serialize for SecurityOutput<Config, Gate>
where Config: Serialize, Gate: Serialize,

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

§

impl<Config, Gate> Freeze for SecurityOutput<Config, Gate>
where Config: Freeze, Option<Gate>: Freeze,

§

impl<Config, Gate> RefUnwindSafe for SecurityOutput<Config, Gate>
where Config: RefUnwindSafe, Option<Gate>: RefUnwindSafe,

§

impl<Config, Gate> Send for SecurityOutput<Config, Gate>
where Config: Send, Option<Gate>: Send,

§

impl<Config, Gate> Sync for SecurityOutput<Config, Gate>
where Config: Sync, Option<Gate>: Sync,

§

impl<Config, Gate> Unpin for SecurityOutput<Config, Gate>
where Config: Unpin, Option<Gate>: Unpin,

§

impl<Config, Gate> UnsafeUnpin for SecurityOutput<Config, Gate>
where Config: UnsafeUnpin, Option<Gate>: UnsafeUnpin,

§

impl<Config, Gate> UnwindSafe for SecurityOutput<Config, Gate>
where Config: UnwindSafe, Option<Gate>: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<'a, T> FromIn<'a, T> for T

Source§

fn from_in(t: T, _: &'a Allocator) -> T

Converts to this type from the input type within the given allocator.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<'a, T, U> IntoIn<'a, U> for T
where U: FromIn<'a, T>,

Source§

fn into_in(self, allocator: &'a Allocator) -> U

Converts this type into the (usually inferred) input type within the given allocator.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more